All hardware with a microphone (or speaker since it too can be used as a mic) needs a hardware switch to disable ... Which will only land once open hardware Linux mobiles take off in next year or two ... Until then I just assume nothing is private
You don't need linux support to put a switch on a microphone
Alexa and Google Home expose users to vishing and eavesdropping
11–20 of 64 posts
Re: Alexa and Google Home expose users to vishing and eavesdropping
#12Newsflash: computing device with the capability for user interaction can request information that you might not want to give it.
In other words, how is this situation different from any software running on any other type of computing device?
Re: Alexa and Google Home expose users to vishing and eavesdropping
#13Do these devices record all the time or only after the trigger word (they would need to be always listening for the trigger word) until the end of the statement?
The more important question is: how do we know whether these devices (or a particular subset of them) record all the time or only after the trigger word?
And would we know if they had been recording unnecessarily?
Re: Alexa and Google Home expose users to vishing and eavesdropping
#14> It is possible to ask for sensitive data such as the user’s password from any voice app. Newsflash: computing device with the capability for user interaction can request information that you might not want to give it. In other words, how is this situation different from any software running on any other type of computing device?
Back in 1966, the makers of the Eliza AI chatbot program were shocked to learn people inherently trusted the program and told it things they didn't want other people to hear. So I propose vishing capitalizes on this phenomena.
Re: Alexa and Google Home expose users to vishing and eavesdropping
#15> Amazon or Google review the security of the voice app before it is published. We change the functionality after this review, which does not prompt a second round review How is this not a massive red flag?
Re: Alexa and Google Home expose users to vishing and eavesdropping
#16> It is possible to ask for sensitive data such as the user’s password from any voice app. Newsflash: computing device with the capability for user interaction can request information that you might not want to give it. In other words, how is this situation different from any software running on any other type of computing device?
i.e. - it's not a new technique, but a new instance of the problem, and that makes it worthwhile (especially for something widely used in private environments) to explore and expose.
It'd be nice if we could reach some kind of device/phone capability plateau and reduce consumption of new equipment. And ideally settle on a small set of software to use on those, which could be hardened and made reliable over time.
Until then, ...
Re: Alexa and Google Home expose users to vishing and eavesdropping
#17Do these devices record all the time or only after the trigger word (they would need to be always listening for the trigger word) until the end of the statement?
The more important question is: how do we know whether these devices (or a particular subset of them) record all the time or only after the trigger word?
a) viewing what they store via their log tools (though this isn't guaranteed to show everything, ie if they are recording everything they couldhide)
b) monitoring outbound network connections
Re: Alexa and Google Home expose users to vishing and eavesdropping
#18All hardware with a microphone (or speaker since it too can be used as a mic) needs a hardware switch to disable ... Which will only land once open hardware Linux mobiles take off in next year or two ... Until then I just assume nothing is private
Re: Alexa and Google Home expose users to vishing and eavesdropping
#19TIL "vishing" is a word. If like me you were wondering what it meant: "Vishing is the telephone equivalent of phishing. It is described as the act of using the telephone in an attempt to scam the user into surrendering private information that will be used for identity theft."
vishing is defined as using social engineering with the intention to get access to the user's vi session. The article is obviously using the term incorrectly.
Re: Alexa and Google Home expose users to vishing and eavesdropping
#20Earlier quoted context omitted.
You don't need linux support to put a switch on a microphone
True, but none of the players that be will add one voluntarily.